Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring Microsoft Sentinel analytics rules. Which THREE of the following are valid types of analytics rules in Microsoft Sentinel?

⚠ Common exam trap

Candidates often confuse watchlists and playbooks with actual analytics rule types, as they are prominent features in Microsoft Sentinel but serve different purposes (data enrichment and automated response, respectively) rather than generating alerts or incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fusion rule

In Microsoft Sentinel, the analytics rule types available when creating a rule include Scheduled query rules (D), which run KQL queries on a defined frequency and trigger alerts based on results; Fusion rules (A), which use Microsoft's machine-learning correlation engine to detect multi-stage attacks across signals; and Microsoft Security rules (B), which create incidents from alerts generated by Microsoft security products like Defender and Microsoft 365. These three are the standard rule types offered in the Sentinel analytics rule wizard. Watchlist rule (C) is not a rule type — watchlists are data sources used to enrich queries and can be referenced inside scheduled rules, not a standalone analytics rule. Playbook rule (E) is also not a rule type — playbooks are Logic Apps used for automated response and are triggered by automation rules or analytics rules, not created as analytics rules themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fusion rule

    Why this is correct

    Fusion rules are the correct answer here because they represent a built-in analytics rule type that uses advanced machine learning to correlate multiple low-severity signals across data sources, detecting multi-stage attacks in near real-time. Existing note: Fusion rules use advanced detection; this applies directly to the question's analytics rule configuration context.

  • ✓

    Microsoft Security rule

    Why this is correct

    Microsoft Security rules are a distinct analytics rule type in Sentinel that automatically create incidents from alerts generated by Microsoft security products such as Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity. They are not the answer to this specific question, but they are a valid analytics rule type when configuring incident creation from native security alerts.

  • ✗

    Watchlist rule

    Why it's wrong here

    Watchlist rules are not an analytics rule type; watchlists are static reference data stored in Sentinel that can be used to enrich or filter queries within analytics rules, not standalone scheduled queries or data source detections. During analytics rule configuration, you might select a watchlist as a lookup, but you cannot choose 'Watchlist rule' as the rule type.

  • ✓

    Scheduled query rule

    Why this is correct

    Scheduled query rules are the most common and fundamental analytics rule type in Sentinel; they run a KQL query at a configurable frequency and generate alerts or incidents based on query results, allowing full control over detection logic and threshold tuning. The existing note correctly states this is a common analytics rule type, making it a plausible but incorrect answer for the specific scenario in the question.

  • ✗

    Playbook rule

    Why it's wrong here

    Playbook rules are not an analytics rule type; playbooks are automated response workflows built on Azure Logic Apps that trigger in response to alerts or incidents, not detections themselves. During analytics rule creation, you configure the detection logic (like a scheduled query or Fusion rule), and optionally attach a playbook to automate remediation, but the playbook itself is not a rule type.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.